Home Sectors Services Publications About Contact Book a consultation
Service

AML and Compliance for Digital Assets

We build an AML framework for a crypto business rather than rewriting template documents. With current regulatory requirements, blockchain analytics and the Travel Rule built in.

Duration
Three to eight weeks
Format
Remote
Result
Rules, risk methodology, KYC, KYT and Travel Rule procedures
Book a consultation

What makes crypto compliance different

On top of the risks any financial firm carries, a crypto business adds layers a bank simply does not have.

What is checkedBankCrypto
Fiat transactions, payment details, documents, customer behaviour✓✓
Source of funds on chainLinks to mixers, darknet addresses, sanctioned wallets and bridges.✓
Travel RuleOriginator and beneficiary data on transfers between virtual asset service providers.✓
Privacy and decentralisationPseudonymous addresses, privacy coins, DeFi and cross-chain activity.✓
SpeedResponse is measured in minutes rather than days.✓
Its own laundering typologiesStructuring through address chains, layering across several exchanges, self-hosted wallets.✓

So the rules, the risk assessment and monitoring are built with blockchain analytics and transaction and address screening tools designed in from the start.

How the work runs

  1. We study the business model: spot, derivatives, staking, peer to peer exchange, fiat gateways.
  2. We assess risk with the crypto specifics in front: customer, product, technology, geography and on-chain transaction risk.
  3. We write or adapt the full set of internal control rules for the requirements that apply to digital asset service providers.
  4. We build identification, including enhanced measures for higher risk levels, and the monitoring framework.
  5. We set up Travel Rule processes, handling of suspicious addresses and freezing.
  6. We recommend blockchain analytics tools and embed them into the processes.
  7. We train the team and prepare it for conversations with the regulator and with partner banks.

What we need from you

A description of the products and the technology, current rules if any exist, aggregated data on the customer base and volumes, information about the analytics tools in use, and access to the compliance and product teams.

Access to the product team matters more here than on other projects. In crypto, control is built into the product rather than bolted on top: whatever is not designed into the platform has to be done by hand later.

What you get

Rules for crypto activity

A full set of internal control rules adapted to your products and your technology.

Risk assessment methodology

An assessment with factors an ordinary financial firm does not have, including on-chain transaction risk.

KYC, KYT and Travel Rule procedures

Identification, transaction and address screening, data exchange between providers, escalation and freezing.

Tooling recommendations

Choosing and configuring blockchain analytics for your volumes and products, plus checklists, report templates and risk matrices.

Timing

The timeline depends on the maturity of your current processes and the number of products. A platform where control is partly built in and needs tuning moves faster than a launch from zero. The implementation plan is handed over with the documents, so that the work does not stop at "documents ready".

Frequently asked questions

Can we take ordinary AML rules and edit them lightly?

No. Bank documents describe neither on-chain source of funds analysis, nor the Travel Rule, nor work with self-hosted wallets, and those are exactly what you will be asked about first.

Do we have to buy paid blockchain analytics tools?

There is no requirement to buy a specific product, but you do have to verify the source of funds, and at any meaningful volume that cannot be done by hand. The choice depends on volumes and products: some firms need a basic solution, others a full platform. We help choose and embed the tool rather than reselling licences.

What about self-hosted wallets and decentralised finance?

You need a clear risk appetite policy: what you accept, what you accept with enhanced measures, and what you do not accept at all. That policy then turns into specific rules and limits. The worst option is deciding case by case, every time from scratch.

Our partner bank is reviewing us, not the regulator. Does that change things?

Only the audience. A bank looks at the same things: how you verify customers and the source of funds, what you do with suspicious addresses, and whether you can show it. We prepare material for that conversation separately.

What does it cost?

The fee depends on the number of products, the maturity of current processes and whether the framework is built from scratch or tuned. We name an exact figure after a short conversation and fix the scope in the contract.

Shall we look at your case?

Tell us the task and we will say whether it needs the full piece of work or a narrower one.

Book a consultation

Northhold Advisory is an independent consultancy. We are not affiliated with, and do not represent, the AFM of Kazakhstan, the AIFC (AFSA) or the National Bank of Kazakhstan.

Book a consultation